← Browse

CVE-2026-86439

Medium

Elevated severity or exploit probability.

CVSS base
8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.1%
63.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-22
Published 2026-09-07 · modified 2026-09-08

Description

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.

References

Official: NVD · CVE.org